Welcome to Cockpitbuilders.com. Please login or sign up.

April 18, 2024, 10:17:30 AM

Login with username, password and session length

PROUDLY ENDORSING


Fly Elise-ng
89 Guests, 0 Users
Members
  • Total Members: 4,154
  • Latest: xyligo
Stats
  • Total Posts: 59,640
  • Total Topics: 7,853
  • Online today: 162
  • Online ever: 582
  • (January 22, 2020, 08:44:01 AM)
Users Online
Users: 0
Guests: 89
Total: 89

COUNTDOWN TO WF2022


WORLDFLIGHT TEAM USA

Will Depart in...

Recent

Welcome

Malicious Attack on website

Started by Bob Reed, April 05, 2011, 10:22:08 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Bob Reed

Thanks to the script kiddies we had our work cut out for us today, but all is well again.

fordgt40

Well done and thanks for getting the "warning message" up - at least we knew it wasn`t us and something was in hand

Regards

David

phil744

Nice one Bob, and Jack also for the email :)
---------------------------------------------------------------------
757-200, P3D, LD767,Arduino, panels by some british moron, pile of dead airplane parts and a hammer!

Yeah i got one of these facebook things too http://www.facebook.com/Simvionics

blueskydriver

#3
Did this propogate to CockpitBuilders' members? Each time of trying to log-in, it locked up the IE browser, and after terminating it, there were attempts to make changes to (using) Acrobat Reader.exe.

Normally, Acrobat Reader is not a part of CockpitBuilders as an requirement to use the site. After checking the Task Manager there were at least three-four instances of this exe file present. Terminated them all and that was it, but it still leaves the idea that something could happen and that it's related to this event.

Suggest everyone runs a full scan with Anti-Virus tonight, just in case...

BSD
| FSX | FDS-MIP OVRHD SYS CARDS FC1| PM | PMDG 737-700 | UTX | GEX | UT7 | ASE | REX2 | AES | TSR | IS | TOPCAT | AvilaSoft EFB | OC CARDS & OVRHD GAUGES| SIMKITS | SW 3D Lights | FS2CREW2010 | FSXPassengers | Flight1 AE | MATROX TH2GO-D | NTHUSIM | 3-Mits EW230Ust Proj |

Bob Reed

#4
Quote from: blueskydriver on April 05, 2011, 11:43:01 AM
Did this propogate to CockpitBuilders' members? Each time of trying to log-in, it locked up the IE browser, and after terminating it, there were attempts to make changes to (using) Acrobat Reader.exe.

Normally, this Acrobat Reader is not a part of CockpitBuilders as an requirement to use the site. After checking the Task Manager there were at least three-four instances of this exe file present. Terminated them all and that was it, but it still leaves the idea that something is could happen and that it is related to this.

Suggest everyone runs a full scan with Anti-Virus tonight, just in case...

BSD

No it did not. It was not that kind of attack. All your systems are safe. I have shutdown the Cockpitbuilders mail server for the time being as the server is still under attack I am on it.

blueskydriver

Thanks Bob for fixing all of this.
It was odd how the AcrobatReader.exe kept trying to change things right when the page (browser) locked up, but then again it's IE8. Probably just something to do with IE and AcrobatReader; maybe a cookie fault.
Anyway, thanks again.
| FSX | FDS-MIP OVRHD SYS CARDS FC1| PM | PMDG 737-700 | UTX | GEX | UT7 | ASE | REX2 | AES | TSR | IS | TOPCAT | AvilaSoft EFB | OC CARDS & OVRHD GAUGES| SIMKITS | SW 3D Lights | FS2CREW2010 | FSXPassengers | Flight1 AE | MATROX TH2GO-D | NTHUSIM | 3-Mits EW230Ust Proj |

jackpilot

I ran a complete scan and all is OK.


Jack

Bob Reed

All seems to be as it should at this time. I have restarted the the mail server and will continue to monitor it for the next few hours. I have also contacted the owner of the IP address that was at the heart of this.

Trevor Hale

As Bob has stated, we had one of our First Major attacks on the site early this morning. 

I would like to thank you all for your patience.  We have a great team behind Cockpitbuilders.com and if it wasn't for all of us contributing and pulling together when the $hit hits the fan, we wouldn't have such a great site.

I can only assume the reason for this kind of attack is "Jealousy". It just goes to show you that because we are getting bigger and better someone needs to try to ruin that.  These individuals can not and will not ruin the good thing we have going here.  It is our personal mission to stop as much of this as possible.  If we can keep them out, then we are doing our jobs right, and if not we all just need to work at it harder.

Thank you all again for reporting posts, and helping to keep us informed.

Fortunatly in this case we have the offenders IP address/addresses from this attack, and will continue to follow up with our internal investigation in conjunction with the proper authorities.

Best regards to you all, and lets get the discussion back to building cockpits.

Trev
Trevor Hale

Owner
http://www.cockpitbuilders.com

Director of Operations
Worldflight Team USA
http://www.worldflightusa.com

VATSIM:

Bob Reed

Let me explain a little further as to what happened. We DID NOT HAVE A VIRUS! What we had was an imbedded redirect to a site with reported mailware. The redirect is gone. So all are safe.

jackpilot


Great crew here!
Top "cockpit management"
Thanks guys!
:D


Jack

Sean

I don't know if it's a coicidence, but I got a warning about a rogue .exe file. It's the first I've had in I can't remember how long, so am thinking it might be related.

Sean

Bob Reed

It's just a coincidence. Attacks are heavy from all sources, on anyone using the internet right now. I keep getting shipping notices from  DSL, UPS and USPS. I am not waiting for any packages! So what do we think that is? Oh yes and all of them have a file attached.

Like the Website ?
Support Cockpitbuilders.com and Click Below to Donate